Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ureport v2.2.9 代码问题漏洞
Vulnerability Description
UReport是一个基于Spring架构的高性能纯Java报表引擎,可以通过迭代cell来准备复杂的中式报表和报表。 ureport v2.2.9版本存在安全漏洞。攻击者利用该漏洞通过将特制的XML文件上传到/ureport/designer/saveReportFile来执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A